Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
203 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.33% | — | J-breuer Frontend Checklist | 26/6/2024 | 17/6/2026 | The Frontend Checklist WordPress plugin through 2.3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Analizada | Media (4.3) | 0.33% | — | J-breuer Frontend Checklist | 26/6/2024 | 17/6/2026 | The Frontend Checklist WordPress plugin through 2.3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Aplazada | Crítica (9.8) | 0.41% | — | Buy-addons Complete FOR Create A Quote IN Frontend Backend PROAI | 24/6/2024 | 17/6/2026 | SQL injection vulnerability in the module "Complete for Create a Quote in Frontend + Backend Pro" (askforaquotemodul) <= 1.0.51 from Buy Addons for PrestaShop allows attackers to view sensitive information and cause other impacts via methods `AskforaquotemodulcustomernewquoteModuleFrontController::run()`,… | |
| Aplazada | Alta (7.2) | 0.47% | — | Frontend Registration Contact Form 7AI | 4/6/2024 | 17/6/2026 | The Frontend Registration – Contact Form 7 plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1 due to insufficient restriction on the '_cf7frr_' post meta. This makes it possible for authenticated attackers, with editor-level access and above, to modify the default user… | |
| Aplazada | Crítica (9.8) | 0.54% | — | Glowlogix WP Frontend ProfileAI | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in Glowlogix WP Frontend Profile allows Privilege Escalation.This issue affects WP Frontend Profile: from n/a through 1.3.1. | |
| Aplazada | Alta (7.2) | 0.64% | — | Wedevs WP User FrontendAI | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in weDevs WP User Frontend allows Privilege Escalation.This issue affects WP User Frontend: from n/a through 3.6.5. | |
| Modificada | Alta (8.8) | 71% | 💥 Exploit | Mozilla FirefoxMozilla ThunderbirdDebian LinuxOpen-xchange Appsuite Frontend | 14/5/2024 | 17/6/2026 | A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11. | |
| Modificada | Crítica (9.8) | 0.81% | — | Dynamiapps Frontend Admin | 2/5/2024 | 17/6/2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'fea_encrypt' function in all versions up to, and including, 3.19.4. This makes it possible for unauthenticated attackers to manipulate the user processing forms, which can be used to add and… | |
| Aplazada | Alta (7.5) | 0.68% | — | Buffercode Frontend DashboardAI | 24/4/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in vinoth06. Frontend Dashboard.This issue affects Frontend Dashboard: from n/a through 2.2.2. | |
| Aplazada | Media (6.5) | 0.36% | — | Buffercode Frontend DashboardAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vinoth06. Frontend Dashboard allows Stored XSS.This issue affects Frontend Dashboard: from n/a through 2.2.1. | |
| Modificada | Alta (7.5) | 0.45% | — | Najeebmedia Frontend File Manager | 17/3/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in N-Media Frontend File Manager.This issue affects Frontend File Manager: from n/a through 22.7. | |
| Modificada | Alta (8.8) | 1.1% | — | Vegacorp Display Custom Fields IN THE Frontend - Post AND User Profile Fields | 5/2/2024 | 17/6/2026 | The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Code Injection via the plugin's vg_display_data shortcode in all versions up to, and including, 1.2.1 due to insufficient input validation and restriction on access to that shortcode. This makes it possible… | |
| Modificada | Media (4.3) | 0.47% | — | Josevega Display Custom Fields IN THE Frontend - Post AND User Profile Fields | 5/2/2024 | 17/6/2026 | The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.1 via the vg_display_data shortcode due to missing validation on a user controlled key. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.41% | — | Vegacorp Display Custom Fields IN THE Frontend - Post AND User Profile Fields | 5/2/2024 | 17/6/2026 | The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode and postmeta in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Modificada | Crítica (9.8) | 0.62% | — | Dynamiapps Frontend Admin | 29/12/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Shabti Kaplan Frontend Admin by DynamiApps.This issue affects Frontend Admin by DynamiApps: from n/a through 3.18.3. | |
| Modificada | Alta (8.8) | 0.85% | — | Zabbix ServerZabbix Frontend | 18/12/2023 | 17/6/2026 | The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user. | |
| Modificada | Media (6.5) | 1.0% | — | Najeebmedia Frontend File Manager Plugin | 4/12/2023 | 17/6/2026 | The Frontend File Manager Plugin WordPress plugin before 22.6 has a vulnerability that allows an Editor+ user to bypass the file download logic and download files such as `wp-config.php` | |
| Modificada | Media (6.1) | 0.40% | — | Zabbix Frontend | 3/8/2023 | 17/6/2026 | A security defect was identified in Foundry Frontend that enabled users to potentially conduct DOM XSS attacks if Foundry's CSP were to be bypassed. This defect was resolved with the release of Foundry Frontend 6.225.0. | |
| Modificada | Media (5.4) | 0.73% | — | Open-xchange Appsuite Frontend | 2/8/2023 | 17/6/2026 | The "OX Count" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would require temporary… | |
| Modificada | Media (5.4) | 0.73% | — | Open-xchange Appsuite Frontend | 2/8/2023 | 17/6/2026 | The "OX Chat" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would require temporary… | |
| Modificada | Media (5.4) | 0.66% | — | Open-xchange Appsuite Frontend | 2/8/2023 | 17/6/2026 | Custom log-in and log-out locations are used-defined as jslob but were not checked to contain malicious protocol handlers. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would… | |
| Modificada | Media (5.4) | 0.66% | — | Open-xchange Appsuite Frontend | 2/8/2023 | 17/6/2026 | The "upsell" widget for the portal allows to specify a product description. This description taken from a user-controllable jslob did not get escaped before being added to DOM. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the… | |
| Modificada | Media (5.4) | 0.66% | — | Open-xchange Appsuite Frontend | 2/8/2023 | 17/6/2026 | The users clientID at "application passwords" was not sanitized or escaped before being added to DOM. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would require temporary… | |
| Modificada | Media (5.4) | 0.66% | — | Open-xchange Appsuite Frontend | 2/8/2023 | 17/6/2026 | Frontend themes are defined by user-controllable jslob settings and could point to a malicious resource which gets processed during login. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this… | |
| Modificada | Media (6.1) | 0.57% | — | Zabbix Frontend | 13/7/2023 | 17/6/2026 | Reflected XSS attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script can be activated through Action form fields, which can be sent as request to a website with a vulnerability that enables execution of malicious scripts. |